Cherokee HTTPD不安全特权释放漏洞

漏洞信息详情

Cherokee HTTPD不安全特权释放漏洞

漏洞简介

Cherokee web server 0.2.7之前版本在连结到端口80后不正确的放弃根特权,远程攻击者借助其他漏洞提升特权。

漏洞公告

The vendor has addressed this issue in Cherokee 0.2.7.
Cherokee Cherokee HTTPD 0.1

Cherokee Cherokee HTTPD 0.1.5

Cherokee Cherokee HTTPD 0.1.6

Cherokee Cherokee HTTPD 0.2

Cherokee Cherokee HTTPD 0.2.5

Cherokee Cherokee HTTPD 0.2.6

参考网址

来源:US-CERT Vulnerability Note: VU#245795
名称: VU#245795
链接:http://www.kb.cert.org/vuls/id/245795

来源: BID
名称: 3771
链接:http://www.securityfocus.com/bid/3771

来源: XF
名称: cherokee-http-insecure-privileges(7797)
链接:http://xforce.iss.net/xforce/xfdb/7797

来源: VULNWATCH
名称: 20011229 Remote Root Hole in Cherokee Webserver
链接:http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0085.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享